# Create a custom index in winlogbeat using cloud.id

**URL:** <https://discuss.elastic.co/t/create-a-custom-index-in-winlogbeat-using-cloud-id/179256>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 1, 2019, 8:57pm UTC](https://discuss.elastic.co/t/create-a-custom-index-in-winlogbeat-using-cloud-id/179256 "2019-05-01T20:57:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mdhw3uxhwh](https://avatars.discourse-cdn.com/v4/letter/m/82dd89/32.png) [@mdhw3uxhwh](https://discuss.elastic.co/u/mdhw3uxhwh)\
**Post date:** [May 1, 2019, 8:57pm UTC](https://discuss.elastic.co/t/create-a-custom-index-in-winlogbeat-using-cloud-id/179256/1 "2019-05-01T20:57:06Z")

</div>

Hello,

I have reviewed a [post](https://discuss.elastic.co/t/change-the-default-index-pattern-of-winlogbeat/136478) that contains information on how to accomplish changing the default winlogbeat index name, but it does not seem to work for me.

I have tried exactly what the post provided and it didn't work, so I tried the below:  
setup.template.name: 'winlogbeat-%{[beat.version]}-%{+yyyy.MM}\_custid'  
setup.template.pattern: 'winlogbeat%{[beat.version]}-\*'

```
cloud.id: "XXX:XXXXXX"
cloud.auth: "XXXX:XXXX"
cloud.index: 'winlogbeat-%{[beat.version]}-%{+yyyy.MM}_custid'

```

Nothing seems to work. Any help would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 1, 2019, 10:52pm UTC](https://discuss.elastic.co/t/create-a-custom-index-in-winlogbeat-using-cloud-id/179256/2 "2019-05-01T22:52:47Z")

</div>

Hi Tim, what version of Winlogbeat are you using? And what version of Elasticsearch? And this is on Elastic Cloud?

In 7.0 `beat.version` was replaced with `agent.version`. Additionally there's a new [index lifecycle management](https://www.elastic.co/guide/en/beats/winlogbeat/7.0/ilm.html) feature that could be in play depending on versions that automatically creates new indexes based on criteria like size or time period

---

<div class="post-metadata">

**Author:** ![mdhw3uxhwh](https://avatars.discourse-cdn.com/v4/letter/m/82dd89/32.png) [@mdhw3uxhwh](https://discuss.elastic.co/u/mdhw3uxhwh)\
**Post date:** [May 2, 2019, 3:02am UTC](https://discuss.elastic.co/t/create-a-custom-index-in-winlogbeat-using-cloud-id/179256/3 "2019-05-02T03:02:45Z")

</div>

winlogbeat version 6.6.0 (amd64), libbeat 6.6.0 [2c385a0764bdc537b6dc078a1d9bf11bb6d7bd95 built 2019-01-24 10:45:45 +0000 UTC]

We are on elastic cloud and running 6.7.0

Thanks Andrew

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 30, 2019, 3:05am UTC](https://discuss.elastic.co/t/create-a-custom-index-in-winlogbeat-using-cloud-id/179256/4 "2019-05-30T03:05:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
